- State
- TX
- Covered entity type
- Healthcare Provider
- Individuals affected
- 47,984
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An unauthorized third party obtained administrative-level credentials through a business associate (BA) of Baylor Scott & White Medical Center – Frisco, the covered entity (CE). The incident remained contained within the BA’s network and compromised the protected health information (PHI) of 39,850 individuals from September 22 through September 29, 2018. The types of PHI involved in the breach included demographic and financial information. The CE provided breach notification to HHS. Affected individuals, and the media. OCR’s investigation found that the CE maintained an updated BA agreement with its BA and that, upon learning about the breach, the CE discontinued its relationship with the compromised network, including terminating access to CE’s PHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.